Plamen Petkov
DevSecOps Engineer
I'm a DevSecOps Engineer at Cognyte. I work on securing DevOps processes and Kubernetes clusters across cloud-native, on-prem, and air-gapped environments. Lately I've been deep in software supply chain security: SLSA, in-toto, the kind of stuff that makes you look at your CI pipeline very differently. I also speak at conferences about Kubernetes security and whatever else I happen to find interesting at the time.
Here are some projects I've worked on:
- Bare Proxmox VMs to a fully operational Kubernetes cluster in two commands. Terraform provisions the VMs, Ansible bootstraps the nodes, Flux handles GitOps with SOPS-encrypted secrets. Current cluster runs 3 etcd nodes, 3 control plane nodes, 3 workers, and a GPU node with an RTX 3060 for AI workloads — all on Cilium eBPF networking, Longhorn storage, and Istio ambient mesh.
- Enterprise Kubernetes PlatformDeveloped a comprehensive Kubernetes management solution enabling centralized control across multiple environments (Hub & Spoke Architecture). Built with GitOps principles using ArgoCD, featuring advanced monitoring with Prometheus and Grafana, and implementing zero-trust security architecture. The platform includes specialized node pools for different workload types and automated security compliance checking.
- Cross-Region Logging SystemEngineered a sophisticated logging system bridging multiple regions with enterprise-grade security. Implemented secure log forwarding with multi-layer security including mTLS and HMAC signing, designed security gateways with advanced request validation, and created automated certificate management systems.
- Cloud Resource Optimization PlatformBuilt an intelligent cloud resource management tool featuring automated resource discovery, cost analysis, and governance. Implemented daily automated auditing through GitHub Actions, created an intelligent tagging system for resource lifecycle management, and integrated with cloud storage for result persistence.
- Enterprise CI/CD FrameworkDeveloped a comprehensive suite of reusable CI/CD pipelines powering organization-wide deployments. Features include advanced Docker image building with security scanning, automated vulnerability patching, secure secrets management, and infrastructure cost estimation tools.
- Observability StackArchitected a production-ready observability platform integrating metrics, logs, and traces. Built with modern open-source tools, featuring automated alerts, custom dashboards, and efficient storage solutions for long-term data retention.
- An early homelab project where I started experimenting with Infrastructure as Code, self-hosting, and Kubernetes. Where it all began.
Get to know me:
Born in Pleven, Bulgaria, raised in Madrid, Spain, based in Sofia. Certified Kubernetes Administrator (CKA) and Security Specialist (CKS). I got into tech through website development and game modding, which somehow ended up being a reasonable path to Kubernetes clusters in air-gapped environments. Outside of work I'm either deep in my homelab or going down a mechanical keyboard rabbit hole.
Latest Tweets
Contact me:
Fill the form and I'll get back to you.